ESPectre is a UEFI implant located on a system’s EFI System Partition (ESP) rather than in SPI flash firmware. The provided content identifies it as an ESP-based UEFI threat reported by ESET in October and references it as a bootkit. It is discussed alongside other UEFI-related malware such as FinSpy, and contrasted with SPI-flash firmware implants including LoJax, MosaicRegressor, and MoonBounce. Based on the content, ESPectre resides on the computer’s hard drive ESP, making it an ESP-level UEFI implant rather than a motherboard SPI-flash implant. No additional high-confidence details on its infection vector, payload behavior, threat actor attribution, targeted sectors, or specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UEFI/ESP-level bootkit referenced as a notable public example in the UEFI threat trend discussion; included for comparative context to MoonBounce.
A UEFI implant located on the EFI System Partition (ESP) on disk; can typically be removed by reformatting the drive (unlike SPI flash implants).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.